Billing

Warn

Audited by Snyk on Feb 18, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is explicitly about payment processing and integrations: it names Stripe and Paddle integration, subscription lifecycle management, invoice generation, webhook handling, chargebacks/disputes, marketplace payments, and guidance on token/PCI handling. It references concrete payment operations (e.g., subscription.delete(), cancel_at_period_end, handling amounts in cents, PSP tokens like pm_*/cus_*) and covers charge/refund and marketplace split patterns. These are specific tools and operations for moving and managing money (payment gateways), not generic capabilities — therefore it grants direct financial execution authority.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 18, 2026, 01:02 PM